Skip to content
Tucked.
AboutStories
Explore
AboutStoriesDownloadExplore

Tucked Privacy Policy

Effective date: 9 August 2026
Last updated: 23 August 2026

This Privacy Policy explains how Digital Health Pte. Ltd. (UEN 202237853W) (Digital Health, Tucked, we, us, or our) collects, uses, discloses, stores, and otherwise handles personal data in connection with Tucked.

Tucked includes the website at tucked.co, mobile applications, and related marketplace, ordering, reservation, messaging, social, discovery, seller, payment-facilitation, marketing, and support services (the Platform).

This policy is intended to support compliance with Singapore's Personal Data Protection Act 2012 (PDPA). It applies only to Tucked. Other services operated by Digital Health, including any healthcare service, may have separate privacy policies. Tucked is not a healthcare service, although information a User voluntarily shares about allergies or dietary needs may reveal health-related information.

1. Who is responsible for your personal data

Digital Health is the organisation responsible under the PDPA for personal data in its possession or under its control in connection with Tucked.

Our Data Protection Officer (DPO) contact is:

Data Protection Officer
Digital Health Pte. Ltd.
109 Lorong 1 Toa Payoh
#01-316 Toa Payoh North
Singapore 310109
Email: admin@digitalhealth.sg

Sellers are independent businesses or individuals. When a Seller receives Buyer personal data to accept, prepare, deliver, support, refund, or keep lawful records of an order or reservation, that Seller may be a separate organisation responsible for its own handling of that data. Sellers must comply with the Tucked Terms of Use and applicable data-protection law, but their independent privacy practices are not controlled by this policy.

2. What this policy covers

This policy applies to personal data we handle when you:

  • browse or use Tucked;
  • create or manage an account or profile;
  • enable device location;
  • follow Users or Sellers, save places or posts, create collections, post, comment, react, review, report, or message;
  • create or manage a Seller business, store, menu, listing, payment connection, invoice, or fulfilment setting;
  • place, accept, prepare, fulfil, cancel, refund, or dispute an order;
  • request or respond to a reservation;
  • link a payment method or use a payment provider;
  • subscribe to marketing, respond to outreach, or interact with our communications; or
  • contact support, make a complaint, or otherwise communicate with us.

It does not govern a third party's own website, app, payment page, delivery service, social login, map, or other service, even if linked from Tucked.

3. Personal data we collect

The data we collect depends on the features you use and the role in which you use them.

3.1 Account and identity data

We may collect:

  • display name, email address, password hash, profile image, biography, account roles, and preferences;
  • authentication and session information, token identifiers, login time, and account-security events;
  • identifiers and limited profile information from Google, Apple, or another login provider when you choose social sign-in; and
  • information needed to verify age, identity, authority, fraud risk, or account ownership where reasonably required.

We do not need your Singpass password or social-login password and will never ask you to provide it through Tucked.

3.2 Seller and business data

If you are or may become a Seller, we may collect:

  • legal and trading names, entity or registration number, business type, country, currency, business contact details, store description, address, coordinates, opening hours, fulfilment methods, and photographs;
  • licences, permits, registration, verification status, review notes, and evidence of authority;
  • menu, ingredient, allergen, dietary, price, stock, preparation, packaging, storage, and item information;
  • payment-provider business identifiers, account-connection status, encrypted authorisation tokens, settlement references, invoices, fees, refunds, and payout data; and
  • compliance declarations, complaints, recall and food-safety information, insurance details where requested, and communications with us.

Store profiles may be public. Depending on how the Platform is configured, a Seller's store name, owner display name, store address or area, location on a map, business details, photos, menu, opening hours, and other listing information may be visible to anyone. A home-based Seller should only provide an address for publication if prepared for the related privacy and personal-safety implications.

3.3 Order, reservation, delivery, and transaction data

We may collect:

  • order number, items, quantities, prices, fees, Seller, status, timestamps, fulfilment method, and complaint or refund information;
  • Buyer name, email, delivery address, recipient name, phone number, postal code, delivery instructions, and an address snapshot used to preserve the transaction record;
  • reservation date and time, request and response messages, status, and associated conversation;
  • receipts, invoice records, payment status, provider references, processing fees, platform fees, chargebacks, and refund records; and
  • evidence and communications relating to non-delivery, safety, quality, payment, recall, or disputes.

3.4 Payment data

Online card and PayNow payments are handled by Stripe. Historical transactions from a retired provider may remain in Tucked's records for accounting and legal retention, but that provider is no longer connected to Tucked. Tucked may receive and store:

  • a payment or recurring-billing reference;
  • payment method type, status, timestamps, amount, currency, and provider fee;
  • for a linked card, limited metadata such as brand, last four digits, and expiry month and year; and
  • Seller payment-account connection and authorisation information.

For delivery orders, we also receive and store Lalamove quotation and order identifiers, quoted and actual delivery costs, rider and vehicle details supplied for fulfilment, delivery statuses and timestamps, cancellation reasons, and webhook/reconciliation records.

Tucked is designed so raw card numbers and card security codes do not pass through or persist in our systems when the payment provider hosts or tokenises the payment flow. Do not send payment-card details through messages or support channels.

3.5 Location data

With device or browser permission, we may process precise or approximate location coordinates to show nearby Sellers, places, maps, and relevant content. We may also process search locations and Seller/store coordinates.

You can deny or withdraw device-location permission through your browser or device settings. Tucked may then use a location you enter, a general default location, or provide reduced location features. We do not intend to collect background device location when you are not using a location feature unless we separately explain the feature and obtain any required permission.

3.6 Content, social, and communication data

We may collect:

  • photos, videos, captions, posts, comments, reactions, reviews, ratings, collection titles and notes, saves, follows, and notification preferences;
  • messages between Buyers and Sellers, including edits, deletion markers, reply context, read status, mute and archive settings;
  • reports, moderation decisions, safety complaints, and evidence; and
  • your communications with support, our DPO, or other Digital Health personnel.

Content you post publicly can be seen, copied, or shared by others. Deleting your account or a post may not remove copies already made by others or records we must retain for safety, transactions, disputes, or law.

3.7 Device, log, cookie, and usage data

We and our service providers may automatically collect:

  • IP address, device type, operating system, browser, app version, language, time zone, request time, referring page, pages or features used, clicks, approximate location derived from IP, crash data, and diagnostic logs;
  • security and fraud signals, session events, and network information;
  • identifiers stored in cookies, software development kits, local storage, or similar technologies; and
  • analytics information about how Users navigate and use Tucked.

The web application currently uses browser local storage for account-session information and preferences and may use Google Firebase Analytics. Authentication storage may include access and refresh tokens on the device. Anyone with access to an unlocked device or compromised browser profile may be able to access locally stored information, so keep devices and accounts secure and sign out on shared devices.

3.8 Marketing, outreach, and engagement data

We may collect:

  • newsletter email, display name, audience type, source, consent text and time, subscription status, tags, and engagement;
  • email or message delivery, bounce, opening, click, reply, complaint, and unsubscribe events where supported and lawful;
  • business contact information, website and social profile, business type, public address, rating, and other professional information from public sources or data providers for Seller outreach, verification, or directory administration; and
  • consent, Do Not Call check, suppression, follow-up, and communication history.

3.9 Data inferred or generated

We may generate or infer information such as nearby-result order, suggested content, likely preferences, fraud or safety indicators, account role, Seller verification status, aggregate metrics, and engagement scores. We do not intend to make a decision producing legal or similarly significant effects about an individual solely through automated processing without appropriate safeguards where required.

3.10 AI import data and inferences

If you choose AI import for a recipe, store, or menu, we process the photographs or PDF you select, source-file metadata, the creation flow you selected, and the editable draft returned from that source. The service may extract printed facts and infer limited classifications such as cuisine, course, difficulty, dietary suggestions, positive allergen suggestions, food categories, equipment, or timers. Extracted and inferred fields are labelled for review; AI import does not confirm food safety, prices, ownership rights, legal identity, verification, halal status, or other operational claims, and it does not publish content for you.

AI import source files are kept private and are scheduled for deletion on cancellation or within 24 hours. We may retain the sanitised editable result, provenance, warnings, applied-record mappings, and operational information such as status, timing, retry count, model version, and token counts as part of the related account and creation record. Application logs are designed to record operational metadata rather than extracted document content.

We currently use OpenAI as an AI-processing provider. Selected source content and necessary technical identifiers may therefore be processed on infrastructure outside Singapore as described in section 8. Only upload material you are authorised to use, and review all safety, allergen, price, rights, and ownership details before saving or publishing.

3.11 Sensitive information you choose to provide

You may choose to discuss allergies, intolerances, pregnancy-related restrictions, religious dietary practices, disabilities, or other sensitive circumstances with a Seller. Share only what is necessary. Tucked is not intended for medical records, diagnosis, or emergencies.

4. How we collect personal data

We collect personal data:

  • from you, when you register, enter information, enable a permission, transact, publish content, message, subscribe, report, or contact us;
  • from other Users, for example when a Seller records fulfilment or refund information, a Buyer posts a review, or a User reports content;
  • automatically, through the Platform, servers, logs, cookies, local storage, analytics tools, security systems, and device or browser permissions;
  • from service providers and partners, such as payment providers, identity providers, app stores, maps, cloud and analytics services, delivery providers, and communications providers;
  • from public sources, including public business registers, business websites, social profiles, directories, and government or regulator information; and
  • from authorities or professional advisers, where relevant to a complaint, legal process, safety incident, or compliance matter.

If you provide personal data about another person, you represent that you are authorised to do so and have given any notice or obtained any consent required by law. For delivery recipient details, use the information only with that person's knowledge and for the order.

5. Why we collect, use, and disclose personal data

We may handle personal data for purposes a reasonable person would consider appropriate in the circumstances, including to:

5.1 Provide and administer Tucked

  • create, authenticate, secure, and support accounts;
  • provide profiles, feeds, search, maps, nearby results, saves, follows, collections, notifications, posts, reviews, comments, and messages;
  • onboard and administer Sellers, stores, menus, listings, licences, verification, and payment connections;
  • receive, route, confirm, track, fulfil, invoice, cancel, refund, and keep records of orders and reservations;
  • share necessary Buyer data with the relevant Seller and necessary transaction data with the Buyer;
  • process and reconcile payments, fees, commissions, refunds, and chargebacks;
  • provide receipts, support, account settings, and requested communications;
  • process a recipe, store, or menu source you select to produce an editable, unpublished AI-assisted draft; and
  • remember settings and provide compatible experiences across devices where supported.

5.2 Safety, trust, and compliance

  • verify information and investigate fraud, unsafe food, allergen concerns, misconduct, account compromise, payment disputes, infringement, or Terms violations;
  • moderate and preserve content and communications;
  • prevent spam, abuse, security attacks, unauthorised access, and illegal activity;
  • facilitate recalls, safety notices, dispute evidence, and regulator cooperation;
  • enforce the Tucked Terms of Use and contracts and establish, exercise, or defend legal claims;
  • comply with tax, accounting, court, law-enforcement, sanctions, regulatory, data-protection, and other legal duties; and
  • protect the life, health, safety, property, or rights of Users, the public, Digital Health, and others.

5.3 Operate, analyse, and improve

  • monitor performance, availability, security, and usage;
  • diagnose errors and develop, test, and improve features;
  • understand demand, Seller performance, user journeys, and marketplace health;
  • personalise and rank content, search, recommendations, and notifications; and
  • create aggregated or anonymised statistics, research, reporting, and business insights that do not identify an individual.

5.4 Communicate and market

  • send service messages about accounts, security, orders, reservations, payments, policy changes, support, safety, or recalls;
  • respond to inquiries and complaints;
  • send newsletters, offers, surveys, and marketing where you have consented or another lawful exception applies;
  • identify and contact potential Sellers through lawful business outreach; and
  • measure communication delivery and engagement where lawful.

Service and safety messages are not marketing and may be necessary to operate your account or transaction. You can unsubscribe from marketing without opting out of essential service messages.

6. Consent and other permitted handling

Where the PDPA requires consent, we seek express consent or rely on consent that may reasonably be deemed from your voluntary provision of data and the notified purpose. For example, submitting a delivery address for an order indicates consent to use and disclose it to the relevant Seller and service providers for fulfilment.

We may also collect, use, or disclose personal data without consent where the PDPA or another written law permits or requires it, including for legitimate interests after the required assessment and safeguards, business-improvement purposes, investigations, emergencies, legal claims, publicly available information, or compliance with law.

We will not, as a condition of providing a product or service, require consent beyond what is reasonable to provide it. Where practical, optional marketing and analytics choices should be separate from essential Platform processing.

7. When we disclose personal data

We do not sell personal data. We may disclose it as follows.

7.1 Sellers, Buyers, and other Users

  • A Seller receives information needed for an order, delivery, reservation, message, support issue, receipt, refund, safety event, or legal record. This may include the Buyer's name, email, recipient contact and address, instructions, order, and messages.
  • A Buyer receives the Seller's public and transaction information, status updates, messages, and information needed to identify the contracting Seller and obtain support.
  • Public profile, store, listing, post, review, comment, reaction, follow, and collection information is disclosed according to the feature and settings.
  • A reported User may receive enough information about an allegation to respond, but we may withhold a reporter's identity where appropriate for safety, privacy, or law.

7.2 Service providers and partners

We may use providers for:

  • payment processing and Seller payment connections through Stripe, plus retained historical transaction records;
  • cloud hosting, database, storage, media processing, content delivery, backup, cybersecurity, and monitoring;
  • AI extraction and structured-draft processing, currently including OpenAI when you use AI import;
  • analytics and application services, currently including Google Firebase;
  • maps, geocoding, and location services, currently including Google Maps;
  • identity sign-in, currently including Google and Apple;
  • email, messaging, notifications, support, and customer relationship tools;
  • delivery or fulfilment where a feature expressly uses one, currently including Lalamove;
  • fraud prevention, verification, moderation, and compliance; and
  • legal, accounting, audit, insurance, and other professional services.

Providers may process data only for the services they provide to us or for purposes independently disclosed by them, subject to contracts and law as applicable.

7.3 Legal, safety, and corporate disclosures

We may disclose data:

  • to SFA, PDPC, IRAS, police, courts, tribunals, other authorities, or persons authorised by law;
  • to respond to valid legal process, enforce contracts, protect rights and safety, investigate wrongdoing, or manage a food recall or data breach;
  • to insurers, advisers, claimants, counterparties, and witnesses where reasonably necessary for a claim or dispute;
  • in connection with a genuine financing, restructuring, merger, acquisition, sale, insolvency, or transfer of all or part of the business, subject to appropriate confidentiality and data-protection arrangements; or
  • with your direction or consent.

We assess requests and disclose only what is reasonably necessary or legally required.

8. Overseas transfers

Our providers, their personnel, and technical infrastructure may be located outside Singapore. As a result, personal data may be accessed, stored, or processed in other countries.

This includes source files and related content sent to OpenAI when you voluntarily use AI import. The exact processing location may depend on the provider's infrastructure and sub-processors.

Where the PDPA's Transfer Limitation Obligation applies, we take steps required by law to ensure that transferred personal data receives a standard of protection comparable to the PDPA, unless an exemption applies. These steps may include contracts, provider due diligence, security controls, recognised certifications, or another legally permitted transfer mechanism.

9. Cookies, analytics, and local storage

Tucked may use:

  • essential technologies for authentication, security, network management, checkout, settings, and requested functions;
  • preference technologies to remember interface choices such as feed layout or location mode;
  • analytics technologies such as Firebase Analytics to understand usage, performance, and feature adoption; and
  • local device storage for sessions, account information, preferences, and—in demonstration mode—sample or locally created commerce state.

Some technologies may collect personal data. We will provide notice and obtain consent where required for non-essential analytics or similar purposes. You can use available cookie controls and browser or device settings to restrict cookies, analytics identifiers, or local storage, but blocking essential technologies may prevent sign-in or other features.

You can also use browser controls to delete cookies and site data, reset an advertising or analytics identifier where the operating system permits, or uninstall the app. These steps do not delete transaction or account records held on our servers; contact us for a data request.

10. Marketing and communications choices

10.1 We may send marketing by email, telephone, SMS, instant message, push notification, or another channel only in accordance with applicable consent, Do Not Call, and Spam Control requirements.

10.2 You may opt out through an unsubscribe link, available communication settings, the same channel where offered, or by emailing admin@digitalhealth.sg. We will process the request within the period required by law. We may retain a suppression record so we do not contact you again through the opted-out channel.

10.3 Opting out of marketing does not stop order, payment, security, safety, policy, support, or other non-marketing service messages.

10.4 Push notifications and device permissions can also be managed through device settings.

11. Data accuracy

Please keep account, delivery, Seller, licence, menu, ingredient, allergen, contact, and payment-connection information accurate and current. You can update some data in the Platform or request correction from us.

We may verify information where it is likely to be used to make a decision affecting you or disclosed to another organisation, but you remain responsible for information you provide. Sellers must promptly correct listing and food-safety information before accepting further orders.

12. Retention

We retain personal data only for as long as reasonably needed for the purposes described in this policy or a legal or business purpose. Retention depends on:

  • whether your account is active;
  • the nature and sensitivity of the data;
  • orders, reservations, payments, refunds, tax, accounting, food traceability, recall, and consumer-record requirements;
  • safety, fraud, moderation, dispute, limitation-period, insurance, and legal needs;
  • whether another User needs a continuing transaction record;
  • provider backup and deletion cycles; and
  • requirements or directions under applicable law.

We may keep transaction, invoice, payment, tax, consent, safety, and dispute records after account closure for the applicable legal or business period. We may also retain a minimal suppression list after a marketing opt-out and security information needed to prevent repeated abuse.

Private AI import source objects are scheduled for deletion on cancellation or within 24 hours through application cleanup and storage lifecycle controls. Sanitised drafts and records that you apply to recipes, stores, or menu items follow the retention rules for that account and content.

When identifiable data is no longer needed, we take reasonable steps to delete it, anonymise it, or remove the means by which it can be associated with an individual. Deletion from active systems may not immediately remove securely isolated backups, which are overwritten or deleted on a controlled cycle and not used for ordinary business purposes.

13. Security

We use reasonable administrative, physical, and technical arrangements appropriate to the nature of the data and risks. Measures may include access controls, encryption in transit, encryption of sensitive payment-connection tokens at rest, credential hashing, provider controls, logging, backups, environment separation, and incident response.

No system, transmission, or storage method is completely secure. You should use a strong unique password, protect devices and email accounts, sign out on shared devices, keep software current, avoid sending sensitive data in messages, and notify us promptly of suspected compromise.

If a data breach is notifiable under the PDPA, we will assess and notify the PDPC and affected individuals as required by law. A notification may describe what happened, likely risks, steps we have taken, and steps an affected person should take.

14. Access, correction, withdrawal, and other requests

Subject to the PDPA and applicable exceptions, you may ask us to:

  • provide access to personal data in our possession or control and information about how it was used or disclosed during the preceding year;
  • correct an error or omission in your personal data;
  • withdraw consent for a specified purpose with reasonable notice;
  • close your account or delete or anonymise personal data no longer required for a legal or business purpose; or
  • explain our policies, practices, or complaint process.

Send a clear written request to admin@digitalhealth.sg with the email address associated with your Tucked account, the type of request, and enough detail to identify the relevant data. Do not email passwords, full payment-card details, or unnecessary identity numbers.

We may take reasonable steps to verify identity and authority before acting. If a request would reveal another person's data, prejudice an investigation, threaten safety, breach legal privilege, conflict with retention law, be frivolous or vexatious, or fall within another exception, we may limit or refuse it and explain where appropriate.

We aim to respond within 30 calendar days. If we cannot, we will inform you within that period of the soonest practicable response time. We may charge a reasonable fee for an access request where permitted, after giving a written estimate. Correction requests are not subject to an access fee.

If you withdraw consent, we will explain likely consequences. We will cease the affected collection, use, or disclosure after reasonable notice unless law permits or requires continued handling. Withdrawal from processing necessary for an account or active order may mean we cannot continue the relevant service, but it does not affect legal consequences or processing already lawfully carried out.

15. Account closure and deletion

You can delete your account in the web or iOS app from Account → Privacy & account → Delete account. Tucked shows the applicable retention summary before you confirm, requires you to type DELETE, and requires fresh verification using a sign-in method connected to Tucked. When Sign in with Apple is connected, Apple verification is required so Tucked can revoke that access. You may also contact our DPO if you cannot use the in-app process.

Deletion is unavailable while the account has an active order, requested refund, future accepted or requested reservation, print book in fulfilment, unsettled creator earning, processing payout, or staff responsibility that must first be transferred. This prevents deletion from interrupting another User's order or an outstanding payment obligation.

After successful deletion, we immediately sign out all sessions, remove sign-in identities and private convenience data such as saves, follows, collections, shopping lists, delivery addresses, and saved-payment references, unsubscribe the email from marketing, and replace the profile identity with Anonymous. Seller storefronts, menu items, posts, recipes, and recipe books are removed from public availability. The previous email address may be used to create a new account, but the new account is not reconnected to the deleted account's history.

Closing an account does not erase every record immediately. We retain the minimum records reasonably required for other Users' continuing rights, accounting, payments, food traceability or recalls, disputes, fraud prevention, safety, legal claims, and regulatory obligations. Our current account-deletion schedule is:

  • orders, invoices, refunds, payouts, and hidden store or transaction audit records: generally 7 years after final settlement or closure;
  • necessary reviews and moderation records: generally 2 years, or through an active case;
  • Buyer-Seller conversations: generally 2 years after the last message, or through an active dispute;
  • operational and security logs: generally 12–24 months according to the log class; and
  • uploaded post, recipe, storefront, and related media: removed from public view immediately and scheduled for deletion after 90 days. Profile-avatar objects are scheduled for deletion immediately.

Retained messages and necessary reviews may remain visible to the other participant but display the deleted author as Anonymous. Identifiable payment, delivery, business, and transaction snapshots remain restricted to authorised operational, support, accounting, or legal access. A legal hold or applicable law may extend a period. Securely isolated backups expire through their controlled overwrite cycle and are not restored for ordinary use after account deletion.

16. Children

Tucked accounts, orders, reservations, and Seller features are intended for persons aged 18 or older. We do not knowingly invite a person under 18 to create an account or transact. If you believe a minor has provided personal data contrary to this policy, contact us so we can investigate and take appropriate action.

17. Public and third-party information

Public User Content and Seller listings may be indexed by search engines or shared through Platform links. Changing a setting or deleting content may not immediately remove cached copies held by search engines or third parties.

Third-party services such as Stripe, Lalamove, Google, Firebase, Apple, maps, app stores, or linked sites may collect personal data independently under their own policies. Review their notices before using them. Their independent handling is not governed by this policy, although we remain responsible for our own collection, disclosures, provider instructions, and obligations under applicable law.

18. Changes to this policy

We may update this policy to reflect changes in law, technology, providers, data practices, or Platform features. We will post the new version with its effective date and give reasonable notice of material changes, such as through the Platform, account email, or a renewed consent request where required.

A change will not authorise a materially new collection, use, or disclosure where fresh notice or consent is required by law.

19. Questions and complaints

Please contact our DPO first if you have a question or concern. We will review the matter and respond as soon as reasonably practicable.

Data Protection Officer
Digital Health Pte. Ltd.
UEN: 202237853W
109 Lorong 1 Toa Payoh
#01-316 Toa Payoh North
Singapore 310109
Email: admin@digitalhealth.sg

You may also contact the Personal Data Protection Commission of Singapore through its official channels if you are not satisfied with our response. This does not affect any rights you have under applicable law.

Tucked.

Home-cooked nearby. Made for Singapore’s curious eaters and independent kitchens.

ExploreSingapore kitchensStoriesDownload
CompanyAboutTermsPrivacy
AccountLog inSign upExplore
© 2026 Tucked. Singapore.

Optional analytics help improve Tucked. Privacy details